Virus not caught

Michael St. Laurent mikes at HARTWELLCORP.COM
Tue May 4 21:00:40 IST 2004


Christian Campbell <mailto:ccampbell at BRUEGGERS.COM> wrote:
> I'm running MS 4.28.6-1 on RH8 with ClamAV .70 and F-Prot (4.41
> program / 3.14.11 engine / 3 May 2004 Defs) in front of my
> Exchange 5.5 server running Symantec AV.  MS and AV scanners
> have been catching all my viruses for 6 months or more on my MS
> server, never letting any through to my Symantec AV on Exchange.
>  Recently, I have been receiving virus warnings that Symantec
> has caught Netsky.Q at mm.enc on my Exchange server.  While I'm
> glad Symantec caught it...I'm troubled as to why it's getting
> past MS and AV scanners on my RH8 box.
>
> Running MailWatch reveals that F-Prot is catching
> W32/Netsky.Q at mm, however I don't always trust that AV vendors
> name the variants consistently amongst themselves.
>
> Any suggestions on how I should proceed in troubleshooting this
> issue?  Is anyone experiencing the same?

First, check to make sure that you are still automatically downloading the
updated signature files for ClamAV.

If you are then submit the infected file on the ClamAV web page:

http://www.nervous.it/~nervous/cgi-bin/sendvirus.cgi

Be sure to indicate the name of the virus and that it was caught by
Symantec.

--
Michael St. Laurent
Hartwell Corporation

-------------------------- MailScanner list ----------------------
To leave, send    leave mailscanner    to jiscmail at jiscmail.ac.uk
Before posting, please see the Most Asked Questions at
http://www.mailscanner.biz/maq/     and the archives at
http://www.jiscmail.ac.uk/lists/mailscanner.html



More information about the MailScanner mailing list